CVE Tools

Traefik

21 CVEs tracked since 2026. Since Mar 2026, none of them reached CISA KEV.

Traefik CVEs per month

Mar 2026 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Traefik CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-0380
2026-04null or fewer
2026-05null or fewer
2026-06null or fewer
2026-07null or fewer
2026-08null or fewer
2026-09130

Products

The products that kept showing up in Traefik's monthly top three, with their CVEs summed over those months.

  1. Traefik212 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Traefik.

  1. CVE-2026-88010Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle—
  2. CVE-2026-88012Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded5.3
  3. CVE-2026-88011Traefik: ForwardAuth identity spoofing via dot-form header alias8.1
  4. CVE-2026-88009Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging8.2
  5. CVE-2026-88008Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization9.1
  6. CVE-2026-88007Traefik HTTP/3 Backend NTLM Connection Reuse9.1
  7. CVE-2026-88004Traefik entrypoint header-name sanitization bypassed via request trailers7.4
  8. CVE-2026-88879Traefik before v2.11.56 Identity Spoofing via Header Alias8.2
  9. CVE-2026-88878Traefik v2.8.2 through v3.6 HTTP/3 Timeout Bypass5.3
  10. CVE-2026-88877Traefik v3.7.0 Authentication Bypass via from-to-www-redirect9.8
  11. CVE-2026-85596Traefik v3.7 Authentication Bypass via TLS Option Conflict9.8
  12. CVE-2026-85597Traefik before v2.11.55 and v3.0.0 through v3.7.10 mTLS Bypass via TLS Option Conflict9.1
  13. CVE-2026-85595Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth9.8
  14. CVE-2026-85594Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware9.8
  15. CVE-2026-71327Traefik: Gateway API route identity collision allows cross-namespace backend hijacking8.1

The record

Peak rank
#93 in Sep 2026
Busiest month shown
Sep 2026, 13 CVEs
Months with a KEV entry
0 since Mar 2026
Monthly snapshots
2 since 2026
Traefik's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store